Untrusted Search Path Vulnerability in OpenTelemetry.Resources.Host on macOS
CVE-2026-81192
What is CVE-2026-81192?
The OpenTelemetry.Resources.Host NuGet package is impacted by an untrusted search path vulnerability specifically on macOS systems. Before version 1.16.0-beta.2, the host.id resource attribute detector executes the sh and ioreg commands without specifying an absolute path. This allows an attacker, with less privilege than the host application, to exploit the PATH environment variable and potentially execute arbitrary binaries in the context of the application. Such scenarios enable local code execution and escalate privileges. It is important to note that this vulnerability does not affect Linux or Windows hosts, and there are no known workarounds available for mitigation. A patch is included in version 1.16.0-beta.2.
Affected Version(s)
opentelemetry-dotnet-contrib < 1.16.0-beta.2
